OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
HP-UX 11.0 /usr/lbin/rwrite

btdelfi.lt
Date: Fri May 02 2003 - 12:16:53 CDT


Hi!

There is a vulnerability in /usr/lbin/rwrite on HP-UX 11.0 (other versions might be vulnerable too).

/usr/lbin/rwrite is installed setuid to root by default.

$ /usr/lbin/rwrite something `perl -e 'print "A" x 14628'` something
Segmentation fault

Solution : remove setuid bit until patch is available.

Tried to contact security-alerthp.com , got "Client rejected. Access denied".

Bye,

btdelfi.lt
<--------------------===========================-------------------->
Meiles zinutes sirdies damai ar riteriui: siusk MEILE numeriu 1325.
Jei siunti draugui, po zodzio MEILE nurodyk jo mob. telefono numeri.
Zinutes kaina 1 Lt. http://sms.delfi.lt/